CVE-2020-12891
Severity CVSS v4.0:
Pending analysis
Type:
CWE-427
Uncontrolled Search Path Element
Publication date:
04/02/2022
Last modified:
09/02/2022
Description
AMD Radeon Software may be vulnerable to DLL Hijacking through path variable. An unprivileged user may be able to drop its malicious DLL file in any location which is in path environment variable.
Impact
Base Score 3.x
7.80
Severity 3.x
HIGH
Base Score 2.0
4.40
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:amd:radeon_pro_software:*:*:*:*:enterprise:*:*:* | 21.q2 (excluding) | |
| cpe:2.3:a:amd:radeon_software:*:*:*:*:*:*:*:* | 21.4.1 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



